464 lines
8.7 KiB
YAML
464 lines
8.7 KiB
YAML
|
# -*- mode: yaml; indent-tabs-mode: nil; tab-width: 2; coding: utf-8-unix -*-
|
||
|
---
|
||
|
|
||
|
PROXY_TIME_DAEMON: sdwdate
|
||
|
PROXY_GPG_KEYERVER_URL: hkps://
|
||
|
|
||
|
proxy_masked_services:
|
||
|
- apt-daily-upgrade
|
||
|
|
||
|
# List of proxy packages to install.
|
||
|
proxy_debs_inst:
|
||
|
# Install packages to allow apt to use a repository over HTTPS:
|
||
|
- apt
|
||
|
- apt-transport-tor
|
||
|
- apt-utils
|
||
|
- apt-transport-https
|
||
|
- bootlogd
|
||
|
- ca-certificates
|
||
|
- debsums
|
||
|
- debsecan
|
||
|
- apt-listbugs
|
||
|
- dnsmasq
|
||
|
- ntpdate
|
||
|
- bzip2
|
||
|
- corkscrew
|
||
|
- console-data
|
||
|
- cron
|
||
|
- curl
|
||
|
- less
|
||
|
- mg
|
||
|
- netcat
|
||
|
- ncat
|
||
|
- openssl
|
||
|
- passwd
|
||
|
- patch
|
||
|
- pciutils
|
||
|
- perl
|
||
|
- perl-base
|
||
|
- sudo
|
||
|
- unzip
|
||
|
- xsltproc
|
||
|
- zip
|
||
|
- openssh-client
|
||
|
- openssh-server
|
||
|
- openssh-sftp-server
|
||
|
- nmap
|
||
|
- wireless-tools
|
||
|
- software-properties-common
|
||
|
- lsof
|
||
|
- ifupdown
|
||
|
- iproute2
|
||
|
- iptables
|
||
|
- iputils-ping
|
||
|
- htop
|
||
|
- iotop
|
||
|
- jnettop
|
||
|
- iw
|
||
|
- jq
|
||
|
- python3-argcomplete
|
||
|
- libnet-ifconfig-wrapper-perl
|
||
|
# I need this for Ubuntu even though it come in the bootstrap - 2 setuptools, 1 pip
|
||
|
# - pip
|
||
|
# for pip
|
||
|
- python3-pkg-resources
|
||
|
- python3-pip
|
||
|
- python3-setuptools
|
||
|
# - python3-wheel
|
||
|
# Install packages to allow apt to use a repository over HTTPS:
|
||
|
# niceities from testforge
|
||
|
- file
|
||
|
- findutils
|
||
|
- gcc
|
||
|
- gdisk
|
||
|
- gnupg
|
||
|
- gnupg-utils
|
||
|
- gnupg2
|
||
|
- gpg
|
||
|
- gpg-agent
|
||
|
- gpg-wks-client
|
||
|
- gpg-wks-server
|
||
|
- grep
|
||
|
- groff-base
|
||
|
- haveged
|
||
|
- hostname
|
||
|
- init
|
||
|
- init-system-helpers
|
||
|
- inotify-tools
|
||
|
- install-info
|
||
|
- iso-codes
|
||
|
- kbd
|
||
|
- keyboard-configuration
|
||
|
- klibc-utils
|
||
|
- login
|
||
|
- lsb-base
|
||
|
- lsb-release
|
||
|
- lynx
|
||
|
- make
|
||
|
- man-db
|
||
|
- mount
|
||
|
- nano
|
||
|
- ncurses-base
|
||
|
- ncurses-bin
|
||
|
- ncurses-term
|
||
|
- net-tools
|
||
|
- netbase
|
||
|
- parted
|
||
|
- pinentry-curses
|
||
|
- pm-utils
|
||
|
- policykit-1
|
||
|
- policykit-1-gnome
|
||
|
- policyrcd-script-zg2
|
||
|
- powermgmt-base
|
||
|
- procps
|
||
|
- psmisc
|
||
|
- python-six
|
||
|
- rsync
|
||
|
- sed
|
||
|
- strace
|
||
|
- tar
|
||
|
- traceroute
|
||
|
- tzdata
|
||
|
- upower
|
||
|
- util-linux
|
||
|
- wget
|
||
|
- xz-utils
|
||
|
- geoip-bin
|
||
|
- nss-plugin-pem
|
||
|
- torsocks
|
||
|
- whois
|
||
|
- yamllint
|
||
|
- python3-impacket
|
||
|
- python3-altgraph
|
||
|
|
||
|
proxy_qemu_guest_debs_inst:
|
||
|
- qemu-guest-agent
|
||
|
|
||
|
proxy_pips2_inst: []
|
||
|
|
||
|
proxy_pips3_inst:
|
||
|
- jq
|
||
|
|
||
|
proxy_pips_reinstall:
|
||
|
# pip prerequisites
|
||
|
#? - distlib
|
||
|
#? - lockfile
|
||
|
- jq
|
||
|
# pip itself? NO
|
||
|
#
|
||
|
# whonix general
|
||
|
- acpi-support
|
||
|
- acpi-support-base
|
||
|
- acpid
|
||
|
- adduser
|
||
|
- busybox
|
||
|
- console-common
|
||
|
- console-data
|
||
|
- console-setup
|
||
|
- console-setup-linux
|
||
|
- coreutils
|
||
|
- cpio
|
||
|
|
||
|
cntlm_pid_file: /var/run/cntlm/cntlm.pid
|
||
|
|
||
|
|
||
|
# BOX_OS_FLAVOR in ['WhonixGateway']}}"
|
||
|
proxy_gateway_debs_inst: []
|
||
|
|
||
|
# BOX_OS_FLAVOR in ['KickSecure', 'WhonixGateway', 'WhonixWorkstation']
|
||
|
proxy_xfce_debs_inst:
|
||
|
- apt-transport-https
|
||
|
- libnetfilter-conntrack3
|
||
|
- dnsmasq-base
|
||
|
- dnsmasq
|
||
|
- firmware-linux-free
|
||
|
- firmware-misc-nonfree
|
||
|
- firmware-amd-graphics
|
||
|
- firmware-linux-nonfree
|
||
|
- firmware-linux
|
||
|
- firmware-atheros
|
||
|
- firmware-iwlwifi
|
||
|
#linux-headers-5.8.0-0.bpo.2-amd64
|
||
|
#linux-image-5.8.0-0.bpo.2-amd64
|
||
|
- ntpdate
|
||
|
- corkscrew
|
||
|
- cron
|
||
|
- mg
|
||
|
# No package matching 'liblua5.3' is available
|
||
|
# - liblua5.3
|
||
|
- netcat-traditional
|
||
|
- netcat
|
||
|
- ncat
|
||
|
- xsltproc
|
||
|
- openssh-client
|
||
|
- openssh-server
|
||
|
- openssh-sftp-server
|
||
|
- nmap-common
|
||
|
- libgfortran5
|
||
|
- libblas3
|
||
|
- libncurses-dev
|
||
|
- libreadline-dev
|
||
|
- nmap
|
||
|
- wireless-tools
|
||
|
- gir1.2-glib-2.0
|
||
|
- gir1.2-packagekitglib-1.0
|
||
|
- python3-dbus
|
||
|
- libgirepository-1.0
|
||
|
- python3-gi
|
||
|
- python3-pycurl
|
||
|
- python3-software-properties
|
||
|
- software-properties-common
|
||
|
- ifupdown
|
||
|
- libpcap0.8
|
||
|
- libnfnetlink0
|
||
|
- libnftnl11
|
||
|
- libiptc0
|
||
|
- libnetfilter-conntrack3
|
||
|
- iptables
|
||
|
- htop
|
||
|
- iotop
|
||
|
- libpcap0.8
|
||
|
- jnettop
|
||
|
- python3-argcomplete
|
||
|
- libnet-ifconfig-wrapper-perl
|
||
|
# I need this for Ubuntu even though it come in the bootstrap - 2 setuptools, 1 pip
|
||
|
#pip
|
||
|
#! python-cryptography
|
||
|
#! python3-pkg-resources
|
||
|
#! apython3-pip
|
||
|
#! python3-setuptools
|
||
|
#! python3-wheel
|
||
|
- install-info
|
||
|
- lynx-common
|
||
|
- lynx
|
||
|
- ncurses-term
|
||
|
- rsync
|
||
|
- traceroute
|
||
|
- tzdata
|
||
|
- geoip-bin
|
||
|
- nss-plugin-pem
|
||
|
- torsocks
|
||
|
- whois
|
||
|
## non-qubes-whonix-gateway-xfce
|
||
|
- xauth
|
||
|
# kicksecure-desktop-applications-recommended : Depends: monero-gui
|
||
|
- libpackagekit-glib2-18
|
||
|
# kicksecure-xfce-vm: kicksecure-cli-vm, kicksecure-xfce, kicksecure-network-conf-gui, non-qubes-audio, non-qubes-vm-enhancements-gui, kicksecure-desktop-applications-recommended
|
||
|
|
||
|
## The following NEW packages will be installed:
|
||
|
## apt-transport-https corkscrew cron dnsmasq dnsmasq-base
|
||
|
## firmware-amd-graphics firmware-atheros firmware-iwlwifi firmware-linux
|
||
|
## firmware-linux-free firmware-linux-nonfree firmware-misc-nonfree geoip-bin
|
||
|
## gir1.2-glib-2.0 gir1.2-packagekitglib-1.0 htop ifupdown install-info iotop
|
||
|
|
||
|
# No package matching 'liblua5.3' is available## # xiptables jnettop libblas3 libgfortran5 libgirepository-1.0-1 libip6tc0
|
||
|
## libiptc0 libiw30 liblinear3 liblua5.3-0 liblua5.3-0-dbg liblua5.3-dev
|
||
|
## libncurses-dev libnet-ifconfig-wrapper-perl libnetfilter-conntrack3
|
||
|
## libnfnetlink0 libnftnl11 libpackagekit-glib2-18 libpcap0.8 libreadline-dev
|
||
|
## lynx lynx-common mg ncat ncurses-term netcat netcat-traditional nmap
|
||
|
## nmap-common nss-plugin-pem ntpdate openssh-client openssh-server
|
||
|
## openssh-sftp-server polipo python3-argcomplete python3-dbus python3-gi
|
||
|
## python3-pycurl python3-software-properties rsync scurl
|
||
|
## software-properties-common torsocks traceroute whois wireless-tools xauth
|
||
|
## xsltproc
|
||
|
|
||
|
# RAW complete overlap
|
||
|
|
||
|
|
||
|
whonix_gateway_debs:
|
||
|
- apparmor
|
||
|
- apparmor-utils
|
||
|
- arc-theme
|
||
|
- auditd
|
||
|
- basez
|
||
|
- bash
|
||
|
- bash-completion
|
||
|
- bc
|
||
|
- bind9-host
|
||
|
- binutils
|
||
|
- binutils-common
|
||
|
- binutils-x86-64-linux-gnu
|
||
|
- bsdmainutils
|
||
|
- bsdtar
|
||
|
- bsdutils
|
||
|
- bubblewrap
|
||
|
- cryptsetup
|
||
|
- cryptsetup-bin
|
||
|
- cryptsetup-initramfs
|
||
|
- cryptsetup-run
|
||
|
- dash
|
||
|
- dbus
|
||
|
- dbus-user-session
|
||
|
- dconf-gsettings-backend
|
||
|
- dconf-service
|
||
|
- debconf
|
||
|
- debsums
|
||
|
- desktop-file-utils
|
||
|
- dialog
|
||
|
- dictionaries-common
|
||
|
- diffutils
|
||
|
- dirmngr
|
||
|
- distro-info-data
|
||
|
- dkms
|
||
|
- dmidecode
|
||
|
- dmsetup
|
||
|
- dnsutils
|
||
|
- dpkg
|
||
|
- dpkg-dev
|
||
|
- e2fslibs
|
||
|
- e2fsprogs
|
||
|
- eatmydata
|
||
|
- elpa-auto-complete
|
||
|
- elpa-concurrent
|
||
|
- elpa-ctable
|
||
|
- elpa-deferred
|
||
|
- elpa-epc
|
||
|
- elpa-jedi
|
||
|
- elpa-jedi-core
|
||
|
- elpa-popup
|
||
|
- elpa-python-environment
|
||
|
- exo-utils
|
||
|
- faketime
|
||
|
- fdisk
|
||
|
- fontconfig
|
||
|
- fontconfig-config
|
||
|
- fonts-dejavu-core
|
||
|
- gettext-base
|
||
|
- gir1.2-atk-1.0
|
||
|
- gir1.2-freedesktop
|
||
|
- gir1.2-gdkpixbuf-2.0
|
||
|
- gir1.2-glib-2.0
|
||
|
- gir1.2-gtk-3.0
|
||
|
- gir1.2-pango-1.0
|
||
|
- glib-networking
|
||
|
- glib-networking-common
|
||
|
- glib-networking-services
|
||
|
- gnome-brave-icon-theme
|
||
|
- gnome-colors-common
|
||
|
- gnome-icon-theme
|
||
|
- gnome-themes-extra
|
||
|
- gnome-themes-extra-data
|
||
|
- gnustep-base-common
|
||
|
- gnustep-base-runtime
|
||
|
- gnustep-common
|
||
|
- gpgconf
|
||
|
- gpgsm
|
||
|
- gpgv
|
||
|
- hicolor-icon-theme
|
||
|
- jitterentropy-rngd
|
||
|
- linux-headers-amd64
|
||
|
- linux-image-amd64
|
||
|
- live-boot
|
||
|
- live-boot-initramfs-tools
|
||
|
- live-tools
|
||
|
- locales
|
||
|
- mawk
|
||
|
- menu
|
||
|
- mime-support
|
||
|
- most
|
||
|
- mousepad
|
||
|
- nyx
|
||
|
- obfs4proxy
|
||
|
- onioncircuits
|
||
|
- openvpn
|
||
|
- os-prober
|
||
|
- p7zip
|
||
|
- p7zip-full
|
||
|
- pv
|
||
|
- pymacs
|
||
|
- pypy
|
||
|
- pypy-ipaddress
|
||
|
- pypy-lib
|
||
|
- pypy-pkg-resources
|
||
|
- pypy-setuptools
|
||
|
- pypy-stem
|
||
|
- python
|
||
|
- python-m2crypto
|
||
|
- python-minimal
|
||
|
- python-pip-whl
|
||
|
- python-pyasn1
|
||
|
- python-six
|
||
|
- python-yaml
|
||
|
- python2
|
||
|
- python2-minimal
|
||
|
- python2.7
|
||
|
- python2.7-minimal
|
||
|
- python3
|
||
|
- python3-apparmor
|
||
|
- python3-dateutil
|
||
|
- python3-distutils
|
||
|
- python3-gevent
|
||
|
- python3-gi
|
||
|
- python3-greenlet
|
||
|
- python3-ipy
|
||
|
- python3-jedi
|
||
|
- python3-lib2to3
|
||
|
- python3-libapparmor
|
||
|
- python3-minimal
|
||
|
- python3-parso
|
||
|
- python3-pkg-resources
|
||
|
- python3-psutil
|
||
|
- python3-pycountry
|
||
|
- python3-pyqt5
|
||
|
- python3-scapy
|
||
|
- python3-sdnotify
|
||
|
- python3-sip
|
||
|
- python3-six
|
||
|
- python3-socks
|
||
|
- python3-stem
|
||
|
- python3-virtualenv
|
||
|
- python3-yaml
|
||
|
- python3.7
|
||
|
- readline-common
|
||
|
- secure-delete
|
||
|
- sensible-utils
|
||
|
- shared-mime-info
|
||
|
- sound-theme-freedesktop
|
||
|
- spectre-meltdown-checker
|
||
|
- spice-vdagent
|
||
|
- sysfsutils
|
||
|
- systemd
|
||
|
- systemd-sysv
|
||
|
- sysvinit-utils
|
||
|
- tor
|
||
|
- tor-geoipdb
|
||
|
- torsocks
|
||
|
- ucf
|
||
|
- udev
|
||
|
- udisks2
|
||
|
- unar
|
||
|
- vanguards
|
||
|
- virt-what
|
||
|
- virtualenv
|
||
|
- vrms
|
||
|
# whonix
|
||
|
- wmctrl
|
||
|
- xxd
|
||
|
- zenity
|
||
|
- zenity-common
|
||
|
- zlib1g
|
||
|
- zsh
|
||
|
- zsh-common
|
||
|
- zulucrypt-cli
|
||
|
- zulupolkit
|
||
|
|
||
|
proxy_libvirt_debs_inst:
|
||
|
- libvirt-daemon-system
|
||
|
- libvirt-clients
|
||
|
- libvirt-daemon
|
||
|
- usbutils
|
||
|
- usb.ids
|
||
|
- libvirt-doc
|
||
|
- virt-manager
|
||
|
- privoxy
|
||
|
|
||
|
proxy_libs_debs: []
|
||
|
|
||
|
proxy_services:
|
||
|
# console-setup.sh Debian - in /usr/local/etc/local.d/Whonix-Lati.rc
|
||
|
- "{{ 'console-setup' if ansible_distribution in ['Ubuntu', 'Debian'] else '' }}"
|
||
|
- bootlogd
|
||
|
- "{{ 'privoxy' if BOX_WHONIX_PROXY_HOST != '' else '' }}"
|
||
|
# FixMe: tie in with
|
||
|
# - "{{ 'privoxy' if PRIV_TOR_TYPE == 'client' else ''}}"
|